Practice tips
Is My Therapy Practice a HIPAA Covered Entity?
Whether cash-pay practices are actually HIPAA covered entities, and where PHI really leaks day to day — workaround habits, not vendor breaches.
Published May 30, 2026 · Updated August 29, 2026 · 8 min read
Are you even a HIPAA covered entity?
If you bill insurance electronically, or your practice transmits health information electronically in connection with a covered transaction, you are almost certainly a HIPAA covered entity as a healthcare provider. Cash-pay-only practices sometimes assume this exempts them — it does not. If you store or transmit protected health information (PHI) in any electronic system, from your scheduling calendar to your intake forms, HIPAA's Security Rule applies to that system regardless of how you bill.
The practical result: your EHR, your client portal, your billing software, and even your email provider if you use it for anything containing PHI are all in scope. Each one needs its own answer to “is this HIPAA compliant,” and each one needs a BAA.
What the vendor is responsible for
When you evaluate practice management software, ask for these in writing before you sign up — not after you've migrated your client list:
- An executed Business Associate Agreement (BAA)available before any PHI is stored, not a vague mention that one “can be provided.”
- Encryption in transit and at restfor chart data, notes, messages, and file attachments — not just the login page.
- Role-based access control so a front-desk seat cannot open clinical notes, and a biller cannot see session content.
- Audit trails that log who viewed or edited a chart, a note, or a portal message, and when.
- Tenant-level data isolationif the platform is multi-tenant — your clinic's data should be logically separated from every other clinic on the same software, not just access-controlled.
- A subprocessor list and breach notification termsso you know who else touches your data (hosting, AI transcription, email delivery) and how fast you'll be told if something goes wrong.
In Ritaja Practice, the BAA is issued at clinic activation, every clinic's data lives in its own scoped database rather than shared rows filtered by an ID column, and every chart or portal access is written to an audit log automatically — not toggled on as an add-on.
What stays your responsibility as the clinic
Software cannot make a practice HIPAA compliant by itself. The Security Rule expects administrative and physical safeguards on your side too, and this is where most violations actually happen — not vendor breaches, but staff workarounds.
Minimum necessary access
Give each staff member their own login, never a shared password. Set the software to log out idle sessions automatically. Review who has admin access every few months and remove it when someone leaves.
Where PHI actually leaks
The most common real-world HIPAA gaps in outpatient practices are not exotic: a clinician texting a client's name and appointment time from a personal phone, a note pasted into a personal email to work on at home, a spreadsheet of client contact info kept outside the EHR “just for scheduling.” None of these involve a hack. They involve PHI leaving a compliant system into a non-compliant one. The fix is process, not software: keep everything — scheduling, notes, messaging, billing — inside one system that already has a BAA, so there's no reason to export.
Training and documentation
HIPAA requires a documented risk analysis and staff training, even for a solo practice. This does not need to be elaborate for a small clinic, but it needs to exist and be dated.
Quick vendor-evaluation checklist
- BAA available and reviewed by you (or your attorney) before signup, not after
- Clear answer on where data is hosted and whether it is US-based if that matters to your state licensing board
- Named subprocessors listed, including any AI or transcription vendor
- Documented breach notification timeline
- Session timeout and unique login enforcement, not optional settings buried in admin
For the technical detail behind each of these — encryption standards, HITECH breach notification timelines, and a full six-point vendor checklist — see the complete HIPAA Compliance for Therapy Practice Software guide.
See also: Ritaja Practice's BAA and the full guide to what a BAA covers.
FAQ
- Do solo cash-pay therapists need HIPAA-compliant software?
- Yes, in almost every case. If you store or transmit protected health information electronically — scheduling, intake forms, notes, billing — the Security Rule applies to that system regardless of whether you bill insurance.
- What is the most common HIPAA mistake in small therapy practices?
- Not a data breach — a workaround. Texting client details from a personal phone, emailing a note home, or keeping a client list in a personal spreadsheet outside the EHR are the most common real-world PHI leaks.
Ready to simplify your practice?
Calendar, notes, billing, payroll, and client portal — in one workspace.
No card required to sign up. Your trial begins when you complete clinic activation. No usage meters and no overage charges — your bill is always your plan rate times your billable clinicians.